CVE-2016-5277: Use After Free
A use-after-free vulnerability with web animations when destroying a timeline
Other sources
Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2016-5277?
CVE-2016-5277 is a use-after-free vulnerability with web animations when destroying a timeline in Mozilla Firefox, Firefox ESR, and Thunderbird.
How severe is CVE-2016-5277?
CVE-2016-5277 has a severity value of 9.8, indicating a critical vulnerability.
How does CVE-2016-5277 impact Mozilla Firefox?
CVE-2016-5277 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) in Mozilla Firefox.
How can I fix CVE-2016-5277 in Firefox?
To fix CVE-2016-5277 in Firefox, update to version 49.0 or higher.
Where can I find more information about CVE-2016-5277?
You can find more information about CVE-2016-5277 on the Mozilla Bugzilla and Mozilla Security Advisories websites.